Skip to content

Managed and Self-Hosted

Operate

V1 supports two explicit trust boundaries. Managed mode runs the control plane and data plane in DAC-operated infrastructure and reaches explicitly approved public HTTPS API and MCP targets. Self-hosted mode uses Helm with customer-managed PostgreSQL, Valkey, IdP, secret manager, OpenTelemetry, SIEM/export, and private-network routing.

  • Operators preparing a managed or self-hosted review.
  • Platform engineers checking dependency and topology claims.
  • Security reviewers verifying no required vendor SaaS runtime path for fully self-hosted mode.

This page is a summary, not the full install runbook. It states the deployment posture and points to the source runbooks for exact Helm values, diagnostics, evidence bundles, backup/restore, and upgrade/drain checks.

Use this when the question is “Can DAC operate this for us?” or “What must stay customer-controlled?”

Use deeper runbooks when you need exact Helm commands, values schema checks, release evidence, or sandbox proof.

Self-hosted V1:

  1. Installs through the Helm chart.
  2. Uses customer-managed PostgreSQL for durable truth, audit metadata, and outbox state.
  3. Uses customer-managed Valkey for hot session and cache state.
  4. References customer-controlled OIDC/SAML/local identity configuration.
  5. References a Vault-compatible or customer secret manager.
  6. Sends telemetry and audit export only to customer-controlled or disabled endpoints by default.
  7. Renders install diagnostics as metadata-only status and reason codes.
  8. Requires signed image, SBOM, release evidence, backup/restore, upgrade/drain, and no-secret proof for release handoff.

Managed V1:

  1. Runs control-plane and data-plane services inside the DAC boundary.
  2. Allows runtime egress only to explicitly approved public HTTPS API and MCP targets.
  3. Requires self-hosted deployment for customer-private targets.
  4. Uses cached policy only inside bounded outage settings.
  5. Fails closed when policy, cache, route, credential, or control-plane state cannot be verified.
  • Missing PostgreSQL, Valkey, identity, secret-manager, OTel, or SIEM/export refs produce install diagnostic reason codes.
  • Enabled payload logging is unsafe unless explicitly redacted and approved.
  • Managed cached policy can expire; runtime must fail closed instead of guessing.
  • No-outbound runtime checks can deny non-customer egress before upstream.
  • Certified air-gapped packaging, Terraform modules, Kubernetes operator behavior, ClickHouse, NATS, Kafka, Redpanda, and managed MCP hosting are outside the V1 default path.

Type set in Geist, Source Serif 4, and Departure Mono.